Root-Cause Analysis (RCA)
Definition
A structured method for identifying the underlying systemic cause of a failure rather than its immediate trigger. Common techniques in incident review include five-whys, fishbone (Ishikawa) diagrams, and fault-tree analysis. The goal is to find the cause whose correction prevents recurrence, not the cause that was most visible during the incident.
- Goal
- Identify underlying systemic cause, not the immediate trigger
- Common techniques
- Five-whys, fishbone (Ishikawa) diagram, fault-tree analysis
- Applied in
- Post-incident review and lessons-learned processes
- Success criterion
- Correcting the found cause prevents recurrence
Common questions
Why does RCA focus on the least visible cause rather than the most obvious one?+
The most visible trigger, such as a single misconfigured server, is often just the last link in a longer chain of contributing factors like inadequate change review or missing monitoring, and fixing only the visible trigger leaves the systemic weakness in place for a repeat incident.
How does the five-whys technique avoid stopping at a superficial answer?+
It repeatedly asks why the preceding cause occurred, typically five times, pushing the analysis past the first plausible explanation until it reaches a process, policy, or design gap that management can actually correct.
What is the risk of treating RCA as a blame-assignment exercise?+
If staff fear personal blame, they tend to withhold details during the review, which produces an incomplete causal chain and an RCA that identifies a scapegoat rather than the systemic condition that actually needs fixing.
Related terms
- Action Item
- A specific, time-bound improvement task generated by a post-incident finding. An action item has a named owner, a target completion date, a...
- Blameless Post-Mortem
- A cultural approach to post-incident review, popularised in site reliability engineering, in which the analysis focuses on systemic and process failures rather...
- Lessons-Learned Register
- A persistent record, maintained by the security programme, that links each post-incident action item to the originating incident, tracks its status, and...
- Post-Incident Activity
- The NIST SP 800-61 label for the final phase of the incident response lifecycle. It encompasses evidence retention, lessons-learned meetings, and the...
- Timeline Reconstruction
- The process of ordering digital events from multiple sources into a single chronological account. Requires normalising all timestamps to a common reference...